Post-Quantum Cryptography: The Board Reading

Post-quantum cryptography stopped being a research curiosity in 2024, when NIST finalised its first three standards, and it became a board-agenda item in 2026, as the deadlines that hang off those standards started landing on procurement and audit. The board does not need to understand lattice mathematics. It needs to understand that the encryption protecting the firm’s long-lived secrets has an expiry date, and that the work to replace it takes years, not months.

Why this is a now problem, not a 2035 problem

The instinct is to file quantum risk under “someday.” Two facts make that the wrong call.

The first is harvest now, decrypt later. An adversary does not need a quantum computer today to threaten data whose confidentiality must last a decade. They can capture encrypted traffic now and decrypt it once the capability exists. Any secret with a long shelf life — health records, state secrets, financial data, long-term contracts — is already exposed to a threat that is being collected against today.

Free · 4 minutes

Do you know where AI is already being used in your business — and what it can see?

Fourteen questions on shadow AI, data exposure, oversight, and governance debt — the gap between how fast AI is arriving and how much control you have over it. Banded finding on screen, full sheet by email.

The second is that the deadlines have teeth and they cluster in the near term. NIST’s FIPS 140-2 cryptographic certificates move to the Historical List on 21 September 2026, after which they no longer satisfy federal procurement. The EU’s NIS Cooperation Group set a national PQC-strategy milestone for the end of 2026. The US national-security acquisition gate under CNSA 2.0 lands on 1 January 2027. None of these is 2035; all of them convert advisory guidance into contract and audit consequences for deals being signed now.

The runway the standards define

NIST’s transition guidance sets the longer horizon: the quantum-vulnerable algorithms most systems rely on today — RSA, ECDSA, ECDH — are set to be deprecated after 2030 and disallowed after 2035, and 2026 US federal direction has hardened those dates into planning deadlines for high-value systems. The finalised replacements (ML-KEM, ML-DSA and SLH-DSA) are production-ready and, in NIST’s words, should be put into use now. The practical reading for a board is that a seven-to-ten-year enterprise migration started today barely reaches the 2035 window comfortably.

What the board should actually ask

  • Do we have a cryptographic inventory? You cannot migrate what you have not mapped. The first deliverable is knowing where and how the firm uses vulnerable cryptography — in applications, certificates, libraries, appliances and suppliers.
  • What is our harvest-now exposure? Which of our data has a confidentiality requirement long enough to matter, and is it protected by algorithms that will not survive?
  • Are we architecting for crypto-agility? The durable capability is not this migration but the ability to swap algorithms by policy rather than re-engineering — because this is not the last transition.
  • What are our suppliers doing? Procurement teams are already putting PQC roadmap questions into security questionnaires; if yours cannot answer them, that is a commercial exposure, not just a technical one.

The firms that treat this as a crypto-inventory-and-roadmap exercise now will migrate on their own schedule. The ones that wait will do it under a procurement deadline, at a premium, with less runway to get it right.

Who this is for

This reading is for:

  • Boards and audit committees adding quantum risk to the agenda
  • CTOs and CISOs asked “are we exposed” and needing a defensible answer
  • Firms selling into government, financial services or regulated supply chains
  • Risk owners who suspect “harvest now, decrypt later” is already happening to them

Sixteen Pillars runs the cryptographic inventory and the migration roadmap, so quantum exposure becomes a plan on your schedule rather than a scramble against a procurement deadline. Pricing is published at /pricing/. If this is live for your organisation and you would like an independent reading, the place to start is a conversation.

Sixteen Pillars is a technology governance consultancy based in Cyprus. Engagements run remote across the EU, UK, and Middle East, with on-site time where the engagement requires it.

Free interactive tool

Website compliance checklist

What your site has to do, based on what it actually does

Answer as much or as little as you like — the list builds as you go. Nothing is stored against your name and no email is required.

Free interactive tool

Interactive deadline calculator

Check which regulations apply to you and when

Regulation across the EU, UK, US and Asia-Pacific has moved considerably in the past eighteen months, and several headline dates have shifted more than once. Twelve questions, about three minutes.

Results are shown on screen — no email required. A dated summary is available to download, and can be sent on if that's more useful. What we do with your answers.

Most technology problems are not technology problems. They are control problems.

The systems exist. The investment has been made. The question is whether leadership can understand, direct, evidence, and sustain what those systems produce. Find out where control exists — and where it only appears to.

Full Governance by Sixteen Pillars

Govern your business. Prove your compliance.

A board assurance cockpit for EU-regulated financial firms — tamper-evident, hash-chained proof of governance across DORA, GDPR, NIS2, ISO 27001, the EU AI Act and MiCA. In development.

See what's coming